“Brand loyalty rewards what you bought. Fundle Mall Loyalty rewards where you spent your day — and that data is 10x more valuable to the next campaign.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn
TL;DR
  • Understand why consent based loyalty data management is now a board-level risk and revenue issue for Indian retailers
  • Map how India's Digital Personal Data Protection Act reshapes consent collection across POS, app, and CRM touchpoints
  • Compare legacy loyalty vendors against modern privacy-first architectures purpose-built for Indian retail
  • Follow a five-step playbook to migrate your loyalty database to a DPDP-compliant, consent-gated model
  • See how Fundle AI Platform manages 50+ Indian POS connectors to streamline consent-based data flow at enterprise scale

For most of the last decade, Indian retail loyalty programs operated on a quiet, largely unspoken assumption: that a customer who handed over a mobile number at a Pantaloons till or enrolled in a Phoenix Marketcity rewards app had implicitly consented to everything that followed — win-back SMS campaigns, cross-brand data sharing, third-party credit scoring, the works. That assumption is now legally and commercially untenable.

The Digital Personal Data Protection Act, 2023 — India's first comprehensive data privacy law — redraws the contract between retailer and shopper. Consent must be free, specific, informed, and unambiguous. It must be as easy to withdraw as it is to give. And crucially, it must be purpose-limited: collecting a customer's purchase history to award loyalty points does not automatically authorise you to share that history with a co-branded insurance partner or a fintech. For CMOs and CIOs who built their loyalty stacks on broad, catch-all consent clauses, the gap between current practice and DPDP compliance is not a tweak — it is a structural rebuild.

Consent based loyalty data management is the discipline of designing, capturing, storing, and honouring granular, purpose-specific customer permissions across every touchpoint in the loyalty lifecycle — POS, mobile app, WhatsApp, web, in-store kiosk, and call centre. Done well, it is not merely a compliance checkbox. Brands like Tanishq, Manyavar, and Lenskart that get consent architecture right will hold richer, more reliable first-party data than competitors who scraped broad permissions and now face deletion requests and regulatory scrutiny. Privacy, in this framing, is a data-quality strategy as much as a legal one.

Fundle was founded on the belief that Indian retail deserved an AI-first loyalty platform that treated consent as a first-class data object — not an afterthought bolted onto a legacy CRM. This article is a practitioner-level guide for the Indian retail CMO or CIO who needs to understand what best-in-class consent management looks like, why the window to act is narrowing, and how to build a loyalty data infrastructure that survives and thrives in the DPDP era.

Indian Retail Loyalty & Data Privacy: Four Numbers That Set the Stage

₹4,200 Cr+
Estimated annual value of loyalty-driven incremental GMV across India's top 20 mall operators — most of it built on consent practices that pre-date DPDP
73%
Share of Indian online shoppers who say they are more likely to share personal data with a brand that clearly explains how it will be used (IAMAI–Kantar, 2023)
50+
Indian POS connectors managed by Fundle AI Platform to streamline consent-based data flow across retail and mall environments
₹250 Cr
Maximum penalty per instance of data breach under DPDP Act, 2023 — a figure that makes consent architecture a CFO conversation, not just a legal one

Why Consent Is the Load-Bearing Wall of Modern Loyalty Programs

Strip away the gamification, the tier names, and the anniversary emails, and a loyalty program is fundamentally a data exchange. A customer shares her identity, her purchase behaviour, and her communication preferences; a retailer gives back points, personalised offers, and early access. That exchange only holds when both parties trust the terms. Consent is the legal and psychological instrument that establishes those terms.

In practice, Indian retailers have historically treated consent as a UX afterthought. A single pre-ticked checkbox at enrollment — 'I agree to receive communications' — was considered sufficient to unlock unlimited data use across owned, operated, and partner channels. Capillary, EasyRewardz, and older builds on WebEngage or MoEngage were configured accordingly: ingest everything, segment broadly, push hard. The approach delivered short-term open rates but eroded long-term trust. India's telecom regulator TRAI clocked over 800 million DND registrations by 2023 — a number that reflects a consumer population that felt overwhelmed by unsolicited outreach and had no other recourse.

Consent based loyalty data management changes the architecture at the foundation. Instead of a single binary opt-in, a well-designed consent framework captures permission at the level of individual data use cases: transactional communications (receipts, point balances), promotional outreach (offers, campaigns), third-party data sharing (co-branded partners, affiliates), and analytical profiling (AI-driven personalisation, churn prediction). Each permission is timestamped, version-controlled, and stored as a consent record that can be audited and acted upon — including when a customer exercises her DPDP right to withdraw or erase.

For a retailer like Apollo Pharmacy running a multi-crore member loyalty base, the operational complexity of granular consent management is significant. But the upside is equally significant: a database of 80 lakh members who have affirmatively consented to personalised health product recommendations is orders of magnitude more valuable — commercially and legally — than a database of 2 crore members enrolled via sweepstakes with no memory of what they agreed to. Quality beats quantity once DPDP enforcement begins. Brands that understand this are already investing in consent infrastructure. Those that do not will face a painful, costly remediation.

The Consent Lifecycle in a DPDP-Compliant Loyalty Program

11. Enrollment (POS / App / Kiosk)22. First Engagement (Welcome Journey)33. Ongoing Engagement (Campaigns)44. Consent Update (Preference Centre)55. Deletion / Erasure Request
Every loyalty interaction — from first enrollment to win-back campaign — must map to a specific, timestamped consent record. This journey shows how consent flows across touchpoints in a privacy-first loyalty architecture.

Indian Consumer Sentiment Toward Data Privacy and Consent

It would be a strategic mistake to treat DPDP compliance purely as a regulatory burden. The consumer data behind the law is clear: Indian shoppers are more privacy-aware than they were five years ago, and they are increasingly willing to act on that awareness — by unsubscribing, deleting accounts, or simply refusing to enroll in programs that feel extractive.

A 2023 LocalCircles survey found that 68% of Indian internet users had received unsolicited marketing calls or messages from brands they had shopped with 'only once or twice.' Of that group, 54% said they became less likely to return to the brand. This is not an abstract privacy concern — it is a direct NPS and repeat-visit problem. For a Select CITYWALK or a Reliance Trends store operating on margins where a single incremental visit per customer per quarter moves the P&L, that 54% attrition signal should be alarming.

Younger Indian consumers — the cohort that is disproportionately valuable to aspirational retail brands — hold notably different expectations. Millennials and Gen Z shoppers who grew up with UPI, Aadhaar consent flows, and DigiLocker are familiar with the idea that data sharing should be purposeful and revocable. A FabIndia loyalty program that offers a transparent preference centre and clear explanations of data use will resonate more authentically with this demographic than one that offers bigger discounts but feels opaque about what it does with purchase history.

The commercial implication is that consent, communicated well, becomes a trust signal and a differentiation tool. Manyavar ran a pilot in 2023 where its app explicitly displayed 'what we know about you' and offered customers a one-tap way to update preferences. Engagement with the preference centre drove a 19% uplift in email open rates among members who actively managed their settings — because those members felt in control, and felt the brand respected that control. Consent based loyalty data management, done with design intent, is a retention engine. Brands that frame it only as compliance are leaving retention value on the table.

Legacy Loyalty Consent vs. DPDP-Compliant Privacy-First Loyalty Architecture

Legacy Approach (Pre-DPDP)
Privacy-First Loyalty Platform (DPDP-Compliant)
Single omnibus checkbox at enrollment; no purpose specificity
Granular, purpose-level consent at enrollment with plain-language descriptions of each use case
Consent stored as a boolean flag in CRM; no audit trail or version history
Consent stored as a structured record with timestamp, channel, version, and withdrawal history
Third-party data sharing enabled by default; opt-out buried in FAQs
Third-party sharing requires explicit, separate consent; default is always off
Withdrawal process involves a call centre or multi-step email chain; no guaranteed SLA
One-tap preference centre; withdrawal propagates to all connected systems within 24 hours
No automated suppression; non-consented customers regularly receive campaigns
AI-driven consent check before every campaign dispatch; non-consented segments auto-suppressed

Technologies Enabling Consent Based Management at Scale

Consent based loyalty data management is not a policy document — it is an engineering problem. At the scale of an Indian mall operator running a unified loyalty program across 150 brands and 40 lakh members, or a pharmacy chain with 1,200 outlets across 18 states, consent management requires a purpose-built technology stack that can handle real-time consent checks, multi-system synchronisation, and audit-grade logging without introducing latency at the point of sale.

The three core technology pillars are: a Consent Management Platform (CMP) that captures and stores granular permission records; an AI-driven campaign orchestration layer that enforces consent rules before any outreach is triggered; and a POS and API integration layer that ensures consent data flows bidirectionally between the loyalty platform and every touchpoint where a customer interaction occurs. The last pillar is where most Indian retailers hit a wall. India's retail POS landscape is extraordinarily fragmented — Petpooja and POSist dominate QSR and casual dining; GoFrugal and Wondersoft are embedded across general retail and pharmacy; proprietary systems run across large-format stores. Any consent management solution that cannot connect to this ecosystem in real time will create dangerous consent gaps.

This is precisely why Fundle AI Platform manages 50+ Indian POS connectors to streamline consent-based data flow — making it one of the deepest integration layers available to Indian retail operators today. When a Cafe Coffee Day outlet processes a loyalty enrollment on a Petpooja terminal, or when a Lifestyle store updates a member's tier on a GoFrugal POS, the consent record in the Fundle AI Platform is updated in real time, not in a nightly batch that creates a window of non-compliance.

Beyond integrations, the AI layer is what transforms consent management from a compliance cost into a business capability. Fundle AI Agents continuously analyse consent records to identify members approaching communication fatigue thresholds, proactively surfacing opt-out risk before it materialises. Fundle Agentic AI can trigger personalised preference-centre nudges — 'You haven't updated your preferences in 18 months; here's what's changed' — that refresh consent currency and simultaneously re-engage dormant members. Consent management, in this architecture, becomes a customer engagement loop rather than a one-time enrollment formality.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

Five-Step Playbook: Migrating to DPDP-Compliant Consent Based Loyalty Data Management

01

Audit Your Current Consent Posture

Pull every consent record in your CRM and loyalty platform. Map each record to the specific data uses it authorises. Identify members enrolled before your current privacy policy was in force — these are your highest-risk segment. Quantify the gap between what your consent records authorise and what your campaigns actually do. For most Indian retailers, this audit will surface a material compliance gap within the first week.

02

Redesign Consent Architecture by Purpose

Work with your legal and product teams to define consent categories: transactional, promotional, analytical, third-party sharing, sensitive data (health, financial). Write plain-language consent strings for each — tested for comprehension at a Class 8 reading level in the relevant regional language. Your consent architecture must work in Hindi, Tamil, Telugu, Kannada, and Bengali at minimum, not just English. Build this into enrollment flows at every touchpoint: POS, app, web, kiosk, and call centre.

03

Deploy a Real-Time Consent Management Layer

Implement a CMP that stores consent as a structured, versioned record and exposes a real-time API that your campaign orchestration tools, CRM, CDP, and POS connectors can query before any data use. The consent check must be non-negotiable in your campaign workflow — not a manual checklist but an automated gate. Platforms like Fundle Loyalty are architected with this gate built into the campaign dispatch engine.

04

Re-Consent Your Existing Database Strategically

Do not send a single mass re-consent blast — it will tank your deliverability and alert members to a problem before you have a solution to offer. Instead, sequence re-consent across journeys: embed it in your next tier-renewal communication, your anniversary reward, your post-purchase receipt. Make re-consent feel like a value exchange — 'Update your preferences to get offers that are actually relevant to you' — not a legal formality. Track re-consent conversion by segment and double down on high-converting journeys.

05

Instrument Consent KPIs and Governance Cadence

Consent management is not a one-time project. It requires ongoing measurement: consent capture rate by touchpoint, withdrawal rate by purpose category, time-to-propagation for withdrawal requests, and percentage of campaigns dispatched with full consent coverage. Assign a Data Protection Officer or loyalty data steward accountable for these KPIs. Build a quarterly consent health review into your loyalty governance calendar alongside standard metrics like redemption rate and NPS.

Impact of DPDP on Consent Collection and Loyalty Operations

The Digital Personal Data Protection Act, 2023 is not India's first attempt at data regulation, but it is the first with genuine teeth and a realistic enforcement timeline. The Data Protection Board — the adjudicatory body created under the Act — is expected to be operational by late 2025, and the Ministry of Electronics and Information Technology has signalled that retail, e-commerce, and financial services will be early enforcement priorities given the volume of consumer data they process.

For loyalty program operators specifically, the DPDP Act creates four non-negotiable obligations that go beyond anything in the pre-existing IT Act framework. First, consent must be verifiable — a retailer cannot simply assert that consent was obtained; it must be able to produce a timestamped, purpose-specific record. Second, children's data requires parental consent, which has significant implications for youth-oriented brands like those running programs through college campuses or youth fashion retail. Third, data minimisation is now a principle, not a preference — collecting purchase history is fine; collecting a customer's contact list to find 'similar customers' is not, without explicit separate consent. Fourth, cross-border data transfers require specific mechanisms that most Indian retail loyalty programs have never had to think about, but which are now material for any brand using a cloud-based CDP or loyalty platform hosted outside India.

The operational impact on loyalty teams is immediate. Campaign calendars need consent-coverage checks before deployment. Enrollment forms need to be redesigned — a process that typically takes 3-6 months when you account for legal review, UX design, POS vendor coordination, and staff training. Data retention policies need to be codified and enforced: you cannot hold a customer's data indefinitely simply because she once enrolled in your loyalty program. And critically, your loyalty platform vendor needs to be a DPDP-compliant data fiduciary or data processor — a status that vendors like Capillary, Antavo, Xeno, or Customer Capital will need to formally certify.

Brands that treat DPDP as a compliance project to be completed by a deadline will miss the larger opportunity. The Act, by forcing the industry toward purpose-limited, consent-gated data collection, will effectively clean the Indian retail data ecosystem — driving out the low-quality, unlawfully collected data that has been polluting campaign performance for years. The retailers who emerge from this transition with clean, consent-rich first-party data assets will have a durable competitive advantage in personalisation, targeting, and customer lifetime value optimisation.

DPDP-Ready Loyalty Consent: Seven Things Every Indian Retail CMO Must Verify
  • Consent records are stored as structured, timestamped, purpose-specific objects — not as boolean flags or unstructured text in a CRM notes field
  • Your loyalty enrollment flow captures separate consent for: transactional communications, promotional outreach, analytical profiling, and third-party data sharing
  • Consent withdrawal is available via a self-serve preference centre reachable within two taps from any loyalty communication, with a guaranteed 24-hour propagation SLA
  • Your POS integration layer — covering all terminals across all store formats — syncs consent updates in real time, not in nightly or weekly batch jobs
  • Your campaign orchestration engine queries the consent record as an automated pre-dispatch gate — no manual override available to marketing ops
  • You have a documented, tested process for responding to DPDP right-to-erasure requests within the statutory timeframe, including purge from backup and archive systems
  • Your loyalty platform vendor has confirmed DPDP data fiduciary or data processor status in writing, with a Data Processing Agreement that specifies sub-processor obligations
“India's retail data advantage will belong to brands that earned consent, not borrowed it. The DPDP Act didn't create this truth — it just made ignoring it expensive.”
VN
Vineet NarangCo-founder, Fundle · LinkedIn

How Fundle Enables Scalable Consent Based Loyalty Data Management

Vineet Narang founded Fundle on a specific conviction: that Indian retail loyalty was drowning in data volume while starving for data quality, and that the path to quality ran directly through consent. The Fundle AI Platform is architected from the ground up as a DPDP compliant loyalty data platform — meaning consent is not a module that was added later, but the structural backbone around which every other capability — segmentation, campaign orchestration, AI personalisation, analytics — is organised.

At the data ingestion layer, Fundle Loyalty connects to 50+ Indian POS systems — including Petpooja, POSist, GoFrugal, Wondersoft, and major ERP connectors — through a real-time API mesh that treats every transactional event as an opportunity to validate, update, or capture consent. When a Manyavar store associate enrolls a new member on a GoFrugal terminal, the consent record is created in Fundle Mall Loyalty or Fundle Brand Loyalty (depending on the operating model) with full purpose tagging, channel attribution, and timestamp. When that same customer visits a Phoenix Marketcity property three months later and updates her communication preferences on a kiosk, the Fundle AI Platform propagates that change to every connected campaign tool and suppression list within minutes — not days.

Fundle AI Agents bring intelligence to consent management that goes beyond passive record-keeping. These agents continuously monitor consent health across the loyalty database: flagging members whose consent records are approaching expiry under configurable re-consent policies, identifying purpose categories where withdrawal rates are spiking (a leading indicator that campaigns in that category are perceived as irrelevant or intrusive), and recommending preference-centre engagement tactics tailored to each member's engagement history. Fundle Agentic AI takes this further, autonomously executing consent refresh journeys — sequencing re-consent touchpoints across SMS, WhatsApp, email, and in-app push in the optimal order for each member — without requiring manual campaign builds from the marketing ops team.

Fundle AI Workflow handles the governance layer: every campaign built in the platform must pass a consent-coverage validation before it can be deployed. If a segment includes members who have not consented to the relevant communication purpose, the Workflow flags the conflict and presents the campaign manager with three options — exclude the non-consented segment, route them to a consent-refresh journey, or escalate for legal review. This is not a nice-to-have UX feature; it is the operational mechanism that prevents DPDP violations at the campaign execution layer. For Indian retail CMOs and CIOs who need to demonstrate compliance to a Data Protection Board inquiry, Fundle's consent audit trail — exportable, tamper-evident, and queryable by member, by purpose, or by time period — is the evidentiary record that transforms a stressful regulatory interaction into a straightforward one.

Frequently asked

What does consent based loyalty data management actually mean in practice for a Indian retailer?+

It means that every data use in your loyalty program — sending a promotional SMS, running an AI personalisation model, sharing purchase history with a co-branded partner — is authorised by a specific, purpose-limited consent record obtained from the customer. It is not a single checkbox at enrollment but a structured permissions framework that captures, stores, and honours granular customer choices across every touchpoint and data use case.

How does the DPDP Act, 2023 change what Indian loyalty programs need to do on consent?+

The Act mandates that consent be free, specific, informed, and unambiguous; that it be as easy to withdraw as to give; that withdrawal be acted upon within a reasonable timeframe; and that data use be purpose-limited. For loyalty programs, this means redesigning enrollment flows, building real-time consent management infrastructure, implementing self-serve preference centres, and ensuring campaign dispatch systems enforce consent rules automatically. Penalties for non-compliance reach ₹250 crore per incident.

Can a small or mid-sized Indian retail brand afford to implement proper consent management?+

Yes — and the cost of not doing so is higher than the cost of doing it. Modern platforms like Fundle AI Platform are designed to make consent management operationally efficient even for brands without large in-house data engineering teams. The 50+ POS connector library means most Indian retailers can connect their existing infrastructure without custom integration work. The ROI case is also clear: consented, preference-managed databases consistently outperform on campaign response rates, reducing media spend waste.

How does Fundle handle consent for multi-brand mall loyalty programs where data might be shared across tenants?+

Fundle Mall Loyalty treats inter-brand data sharing as a distinct consent category that requires explicit, separate opt-in from the member. Members of a mall loyalty program can consent to receiving offers from all tenants, a selected subset, or only the mall operator itself. Each tenant interaction is logged against the member's consent record, and any cross-tenant data flows are blocked by the Fundle AI Platform if the relevant consent is absent. This architecture is purpose-built for India's complex mall-tenant data sharing environment.

What is the difference between Fundle and competitors like Capillary, EasyRewardz, or Xeno on consent management?+

Legacy platforms like Capillary and EasyRewardz were designed in a pre-DPDP environment where consent management was not a core architecture requirement — consent was typically handled as a CRM field rather than a structured data object with its own governance layer. Newer campaign tools like Xeno or WebEngage focus primarily on campaign execution and do not own the full consent lifecycle from POS enrollment through preference management and erasure. Fundle AI Platform was architected specifically for DPDP-era Indian retail, with consent as a first-class object embedded in every layer from POS ingestion to campaign dispatch to analytics.

How long does it typically take to migrate an existing Indian retail loyalty database to a DPDP-compliant consent architecture on Fundle?+

For a mid-sized brand with 10-30 lakh members and 3-5 POS integrations, a full migration — including consent audit, architecture redesign, POS connector deployment, and re-consent campaign sequencing — typically takes 12-20 weeks on the Fundle AI Platform. For large mall operators or enterprise retail groups with complex multi-brand structures, 24-32 weeks is a realistic planning horizon. Fundle's 50+ pre-built POS connectors and templated DPDP consent flows significantly compress the timeline compared to building consent infrastructure from scratch.

About Fundle

Fundle (Fundle.ai · Fundle AI Platform · Fundle Loyalty Platform) is India's AI-native loyalty and customer-engagement infrastructure. Fundle powers Fundle Mall Loyalty, Fundle Brand Loyalty, Fundle AI Agents, Fundle Agentic AI and Fundle AI Workflow across 1.33Cr+ Indian retail members, 123+ malls and 270+ partner brands.

Fundle · Fundle.ai · Fundle AI · Fundle AI Platform · Fundle Loyalty · Fundle Loyalty Platform · Fundle Mall Loyalty · Fundle Brand Loyalty · Fundle AI Agents · Fundle Agentic AI · Fundle AI Workflow

Founder

VNVineet NarangFounder, Fundle.ai · LinkedIn

Vineet Narang founded Fundle to make first-party retail data productive for Indian brands and malls.

Talk to a Fundle expert

Want a Fundle deployment plan for your brand or mall? Ping Abhinav or Anmol directly on WhatsApp.

Free 30-minute working session. We'll share what a Fundle Loyalty Platform, Fundle Mall Loyalty or Fundle Brand Loyalty rollout looks like for your category — with specific numbers, not a deck.

A

Abhinav · Fundle.ai

Loyalty & ADSR Expert · Online

Powered by Fundle AI · Replies in under 30 sec